Unlike DOS attack, this type of DDOS attack is very upset and struck the victim only surely die. Typically 28/11/2010 been DDOS attacks Wikileaks.org site and system completely paralyzed. On 14/02/2012 Hacker group was recently a DDOS attack on bkav.com.vn as system downtime in a day and this hacker group is also taking the entire database of more than 100 thousand accounts include financing account, password forum, email and other personal information. Only with the figure This email also makes network security company bkav much trouble already. Hacker or spam mail sent wrong information to the user's email orders and resulting company will disrepute.
Attacks on system resources
This type of attack on system resources such as CPU, memory, file system, processes, ... Hacker is a set of valid user and is a limited amount of resources on the system. However, Hacker will abuse this access to additional resource requirements. Thus, the system or the valid user will be denied use of natural resources. This type of attack will cause the system can not use the resources because resources have been used up.
2.4.3 A number of security measures to overcome
Reduced setup time and connection standby connection. (Especially with the traditional DOS attack)
Use the software to detect DDOS.
Use a firewall and IDS, IPS to be effective.
2.5 INSERT query SQL (SQL Injection)
2.5.1 Techniques attack
SQL injection is a technique that could allow hackers to take advantage of vulnerabilities in the check data entered in Web applications and system error messages of the database administrator to "insert" (inject) and execute the command SQL illegal (not application developers who anticipate or exception). Its consequences are disastrous because it allows hackers can perform the deletion, correction, ... Do have complete data on the basis of applications, even where the application server is running. This error occurs on the data web applications managed by the system administrator database like SQL Server, MySQL, Oracle, ...
To determine how most Web know SQL injection sticky, add an "' "to the address bar.
Example 1: http://vsmc.com.vn/products.php?cat=68 'notice will appear, as shown below.
đang được dịch, vui lòng đợi..